Communitygithub.com

curiositech/windags-skills

Extend and modify the admin dashboard, developer portal, and operations console. Use when adding new admin tabs, metrics, monitoring features, or internal tools. Activates for dashboard development, analytics, user management, and internal tooling.

¿Qué es windags-skills?

windags-skills is a Claude Code agent skill that extend and modify the admin dashboard, developer portal, and operations console. Use when adding new admin tabs, metrics, monitoring features, or internal tools. Activates for dashboard development, analytics, user management, and internal tooling.

Compatible con~Claude Code~Codex CLI~Cursor
npx skills add https://github.com/curiositech/windags-skills/tree/HEAD/skills/admin-dashboard

Preguntar en tu IA favorita

Abre un nuevo chat con esta habilidad de agente ya precargada.

Documentación

Admin & Developer Suite Development

This skill helps you extend the admin dashboard and build internal tools following the established patterns.

DECISION POINTS

When to Add Tab vs Modify Endpoint vs Create New Tool

Adding New Admin Functionality:
├─ User needs read-only data view?
│  ├─ Data exists in current API? → Modify existing tab
│  ├─ New data type needed? → Add new tab + new endpoint
│  └─ Complex analytics required? → Create dedicated analytics tab
│
├─ User needs to modify system data?
│  ├─ Simple CRUD operations? → Add management tab
│  ├─ Bulk operations needed? → Create operations console tab
│  └─ Multi-step workflow? → Build wizard component
│
├─ Internal developer tooling?
│  ├─ Code inspection/docs? → Add to /dev portal
│  ├─ System monitoring? → Add to /ops console
│  └─ User support tools? → Add to admin dashboard
│
└─ External user functionality?
   → STOP: Use frontend-development skill instead

Tab Content Implementation Strategy

Tab Complexity Assessment:
├─ Simple stats display (< 5 metrics)?
│  → Use StatCard grid pattern
│
├─ Data table with filtering?
│  ├─ < 1000 rows? → Client-side filtering
│  └─ > 1000 rows? → Server-side pagination + search
│
├─ Real-time monitoring?
│  ├─ Updates every 30s+? → Use SWR with refresh interval
│  └─ Updates every 5s-? → Use WebSocket connection
│
└─ Interactive controls?
   ├─ Simple toggles/buttons? → Inline actions
   └─ Complex forms? → Modal dialogs + confirmation flows

FAILURE MODES

1. Database Query Performance Death Spiral

Symptom: Admin dashboard times out or loads slowly (>5 seconds) Detection: Monitor /api/admin/* response times >3s Fix: Add database indexes, implement pagination, cache aggregated stats

-- BAD: Full table scan
SELECT COUNT(*) FROM pageViews WHERE userId = ?

-- GOOD: Use indexed timestamp ranges
SELECT COUNT(*) FROM pageViews WHERE createdAt > NOW() - INTERVAL 24 HOUR

2. Stale Cache Showing Wrong Data

Symptom: Admin sees outdated metrics that don't match recent activity Detection: User reports stats don't change after known actions Fix: Implement cache invalidation on data mutations, add "Last Updated" timestamps

// Add cache busting to mutations
await updateUserData(userId);
await revalidateTag('admin-stats'); // Clear cache

3. Missing Audit Logging

Symptom: Admin actions aren't logged in auditLog table Detection: Check auditLog entries for admin actions in past 24h Fix: Add logAdminAction() calls to ALL admin endpoints

// Required in every admin endpoint
await logAdminAction(admin.id, AuditAction.USER_DATA_VIEW, 'users', userId);

4. HIPAA Violation Data Exposure

Symptom: PHI visible in error messages, logs, or aggregated views Detection: Error contains user email/phone/medical data Fix: Sanitize all error responses, use hashed identifiers in admin views

// BAD: Exposes user email
{ error: "User [email protected] not found" }

// GOOD: Uses anonymous identifiers
{ error: "User ID hash_123abc not found" }

5. Admin Privilege Escalation

Symptom: Regular users can access admin endpoints Detection: Non-admin user receives admin data instead of 403 Fix: Add requireAdmin() check as first line of every admin endpoint

export async function GET(request: Request) {
  const admin = await requireAdmin(); // Must be FIRST
  if (!admin) return Response.json({ error: 'Forbidden' }, { status: 403 });
  // ... rest of handler
}

WORKED EXAMPLES

Adding Production Health Monitoring Tab

Scenario: Add real-time API health monitoring with latency metrics, error rates, and service status.

1. Decision Point Navigation:

  • User needs real-time monitoring → Use SWR with 30s refresh
  • System data, not user data → Add to admin dashboard
  • New data type (API metrics) → Create new tab + endpoint

2. Implementation Steps:

Create endpoint with required patterns:

// src/app/api/admin/health/route.ts
export async function GET(request: Request) {
  const admin = await requireAdmin(); // Security first
  if (!admin) return Response.json({ error: 'Forbidden' }, { status: 403 });
  
  const rateLimitResult = await rateLimiter.check(admin.id); // Rate limiting
  if (!rateLimitResult.allowed) return Response.json({}, { status: 429 });
  
  await logAdminAction(admin.id, 'HEALTH_VIEW', 'metrics', null); // Audit
  
  const metrics = await getHealthMetrics(); // Data fetch
  return Response.json(metrics);
}

Create tab component:

function ProductionHealthTab() {
  const { data: health, error } = useSWR('/api/admin/health', fetcher, {
    refreshInterval: 30000 // Real-time updates
  });
  
  return (
    <div className="space-y-6">
      <div className="grid grid-cols-4 gap-4">
        <StatCard label="API Uptime" value="99.9%" status="good" />
        <StatCard label="Avg Latency" value="45ms" trend="down" />
        <StatCard label="Error Rate" value="0.1%" status="warning" />
        <StatCard label="Active Services" value="12/12" status="good" />
      </div>
    </div>
  );
}

3. Expert vs Novice Differences:

  • Novice misses: Audit logging, rate limiting, HIPAA-safe error handling
  • Expert catches: Cache invalidation strategy, performance monitoring setup, proper error boundaries

QUALITY GATES

  • Admin access control: requireAdmin() check passes with admin user, fails with regular user
  • Rate limiting: Endpoint returns 429 when rate limit exceeded (60 req/min default)
  • Audit logging: Admin action logged to auditLog table with correct action type
  • Performance baseline: Tab loads in <2 seconds with realistic data volume
  • HIPAA compliance: No PHI exposed in error messages or debug output
  • Data validation: Invalid requests return proper 400 errors with safe messages
  • Cache behavior: Data updates within 30 seconds of backend changes
  • Error boundaries: UI gracefully handles API failures without crashing
  • Mobile responsive: Tab layout works on tablet-sized screens (768px+)
  • Real-time updates: Auto-refresh works without memory leaks over 10+ minutes

NOT-FOR BOUNDARIES

Do NOT use this skill for:

  • External user-facing features → Use frontend-development instead
  • Authentication/login flows → Use auth-security instead
  • Database schema changes → Use database-operations instead
  • Email/notification systems → Use communications instead
  • API rate limiting configuration → Use backend-api instead
  • HIPAA compliance setup → Use security-compliance instead
  • Performance optimization → Use optimization instead

Delegate to other skills when:

  • Adding public user features → frontend-development
  • Modifying user authentication → auth-security
  • Creating new API endpoints for external use → backend-api
  • Setting up monitoring infrastructure → devops-infrastructure

Individual skills in this repo

This repo contains 20 individual skills — each has its own dedicated page.

curiositech/windags-skills

Expert in 2000s-era music visualization (Milkdrop, AVS, Geiss) and modern WebGL implementations. Specializes in Butterchurn integration, Web Audio API AnalyserNode FFT data, GLSL shaders for audio-reactive visuals, and psychedelic generative art. Activate on "Milkdrop", "music visualization", "WebGL visualizer", "Butterchurn", "audio reactive", "FFT visualization", "spectrum analyzer". NOT for simple bar charts/waveforms (use basic canvas), video editing, or non-audio visuals.

curiositech/windags-skills

Expert legal research agent for finding and scraping expungement data state by state. Knows authoritative sources, URL patterns, Firecrawl configuration, and 2026 legal landscape.

curiositech/windags-skills

Expert in 3D computer vision labeling tools, workflows, and AI-assisted annotation for LiDAR, point clouds, and sensor fusion. Covers SAM4D/Point-SAM, human-in-the-loop architectures, and vertical-specific training strategies. Activate on '3D labeling', 'point cloud annotation', 'LiDAR labeling', 'SAM 3D', 'SAM4D', 'sensor fusion annotation', '3D bounding box', 'semantic segmentation point cloud'. NOT for 2D image labeling (use clip-aware-embeddings), general ML training (use ml-engineer), video annotation without 3D (use computer-vision-pipeline), or VLM prompt engineering (use prompt-engineer).

curiositech/windags-skills

Implement WCAG 2.2 AA/AAA compliance with automated testing, keyboard navigation, screen reader support, and focus management. Activate on: accessibility audit, WCAG compliance, keyboard navigation, screen reader, aria attributes, axe-core, focus trap. NOT for: design-level accessibility review (use design-accessibility-auditor), color contrast only (use css-in-js-architect).

curiositech/windags-skills

Time-blind friendly planning, executive function support, and daily structure for ADHD brains. Specializes in realistic time estimation, dopamine-aware task design, and building systems that actually work for neurodivergent minds.

curiositech/windags-skills

Designs digital experiences for ADHD brains using neuroscience research and UX principles. Expert in reducing cognitive load, time blindness solutions, dopamine-driven engagement, and compassionate design patterns. Activate on 'ADHD design', 'cognitive load', 'accessibility', 'neurodivergent UX', 'time blindness', 'dopamine-driven', 'executive function'. NOT for general accessibility (WCAG only), neurotypical UX design, or simple UI styling without ADHD context.

curiositech/windags-skills

>- Apply crisis decision-making research to agent routing, uncertainty triage, and coordination failure analysis in time-pressured systems. Use when diagnosing handoff failures, analytical paralysis, or expert judgment under incomplete information. NOT for routine coding, simple CRUD design, or static single-agent tasks with complete information.

curiositech/windags-skills

Conversation patterns and interaction protocols for multi-agent systems. Covers request/response, pub/sub, blackboard, delegation chains, debate, critique, consensus, fan-out/fan-in, supervisor-worker, and peer negotiation. Deep analysis of AutoGen conversation patterns, CrewAI delegation, LangGraph state passing, and FIPA-ACL performatives. Teaches how to design what agents say to each other and in what order. Activate on: "agent conversation", "agent protocol", "multi-agent debate", "agent delegation", "supervisor worker pattern", "agent voting", "consensus protocol", "fan-out fan-in", "agent negotiation", "blackboard pattern", "agent dialogue", "conversation topology", "agent handoff". NOT for: wire format or serialization (use agent-interchange-formats), orchestration infrastructure (use agentic-infrastructure-2026), single agent behavior (use agentic-patterns).

curiositech/windags-skills

Meta-agent for creating new custom agents, skills, and MCP integrations. Expert in agent design, MCP development, skill architecture, and rapid prototyping. Activate on 'create agent', 'new skill', 'MCP server', 'custom tool', 'agent design'. NOT for using existing agents (invoke them directly), general coding (use language-specific skills), or infrastructure setup (use deployment-engineer).

curiositech/windags-skills

AI-powered calendar management and agent-based scheduling coordination. Covers calendar APIs (Google Calendar, CalDAV/iCal), AI scheduling assistants (Reclaim, Clockwise, Motion, Cal.com), building custom calendar agents with MCP, multi-calendar merging, timezone management, focus block protection, meeting fatigue detection, and agent-to-agent meeting negotiation protocols. Activate on: "calendar agent", "AI scheduling", "calendar coordination", "meeting scheduling", "calendar API", "focus time protection", "calendar optimization", "Google Calendar MCP", "Reclaim", "Clockwise", "Motion", "Cal.com", "smart scheduling", "calendar-aware agent", "timezone scheduling", "agent negotiation meetings". NOT for: manual calendar UI component design (use form-validation-architect), project management scheduling or Gantt charts (use project-management-guru-adhd), general time-tracking or pomodoro apps (use adhd-daily-planner for time-awareness), building the agent itself from scratch (use agent-creator).

curiositech/windags-skills

Build and adopt production AI agent infrastructure in 2026. Covers framework selection (LangGraph, CrewAI, AutoGen, MCP), orchestration patterns, evaluation, observability, memory systems, and tool use. Also covers the SOCIAL dimension: how to sell agent infrastructure internally, change management, measuring ROI, building trust in autonomous systems, and scaling adoption across teams. Activate on: "agent infrastructure", "agent framework comparison", "which agent framework", "sell AI tools internally", "agent adoption", "agent observability", "agent evaluation", "MCP architecture", "agentic mesh", "enterprise AI agents", "AI change management", "agent ROI". NOT for: building specific agents (use ai-engineer), designing agent behavior patterns (use agentic-patterns), prompt tuning (use prompt-engineer).

curiositech/windags-skills

Fundamental patterns for effective agentic behavior. Teaches decomposition, tool orchestration, error recovery, context management, quality self-assessment, and knowing when to stop. Model-agnostic principles that make any agent more effective regardless of domain. Activate on: "how should I structure this agent", "agentic workflow", "agent patterns", "multi-step task", "tool orchestration", "/agentic-patterns", "decompose this", "agent best practices", "chain of actions", "when should the agent stop", "agent loop design". NOT for: creating agent infrastructure (use agent-creator), building DAGs (use windags-architect), specific tool implementation.

curiositech/windags-skills

Automated discovery and matching of agent skills for dynamic task routing and capability assessment

curiositech/windags-skills

Cryptographic security for agentic systems — zero-trust agent networking, signed message envelopes (JWS/JWE), capability-based security (ocaps), Merkle tree audit trails, WASM sandboxing, and formal verification. Covers CLI dev tool security, mTLS between agents, permission boundaries (least privilege for AI agents), and supply chain security for skills/plugins. Activate on: "agent security", "zero trust agents", "secure agent communication", "capability-based security", "ocap", "signed messages between agents", "agent audit trail", "sandbox agent execution", "agent permissions", "mTLS agents", "cryptographic verification", "agent supply chain", "OWASP agentic", "prove agent did X", "tamper-proof agent logs". NOT for: application-level SAST scanning (use security-auditor), network firewall rules (use infrastructure), SOC2/HIPAA compliance (organizational), or prompt injection defense (use prompt-engineer).

curiositech/windags-skills

Data structures and serialization formats for agent-to-agent communication. Covers message envelopes, structured output schemas, capability declarations, task handoff payloads, error/retry signaling, and context windows as data structures. Deep comparison of A2A protocol, MCP, OpenAI function calling, and LangChain message types. Teaches when to use rigid schemas vs free-form with validation, typed vs untyped, streaming vs batch. Activate on: "agent message format", "agent communication schema", "agent-to-agent protocol", "A2A protocol", "MCP message format", "structured output for agents", "agent interop", "interchange format", "agent serialization", "task handoff format", "capability declaration". NOT for: what agents say to each other (use agent-conversation-protocols), orchestration topology (use multi-agent-coordination), building agent infrastructure (use agentic-infrastructure-2026).

curiositech/windags-skills

Logic-based agent programming language implementing BDI architecture for practical autonomous agent development

curiositech/windags-skills

>- Design AgentSpeak(L)-style BDI agents with context-guarded plans, selection functions, and intention stacks. Use for interruptible autonomy, agent policy, and multi-agent orchestration in dynamic environments. NOT for simple rule engines, static planners, or centralized workflows.

curiositech/windags-skills

Foundational concurrent computation model where actors communicate exclusively through asynchronous message passing

curiositech/windags-skills

Build production-ready LLM applications, advanced RAG systems, and intelligent agents. Implements vector search, multimodal AI, agent orchestration, and enterprise AI integrations. Use PROACTIVELY for LLM features, chatbots, AI agents, or AI-powered applications.

curiositech/windags-skills

license: Apache-2.0 NOT for unrelated tasks outside this domain.

Skills relacionados